VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3548 CVEsRSS

CVE-2026-85672Critical· 9.8PoC
3w ago

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attac…

▾ Abyssalgetomni-ai · zeroxEPSS 2.6%via NVD
CVE-2026-85667Critical· 9.1PoC
3w ago

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline

xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via t…

▾ AbyssalTeamWiseFlow · xiaobeiEPSS 0.69%via NVD
CVE-2026-61688Medium· 6.5PoC
3w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponen…

▾ TwilightSolidInvoice · SolidInvoiceEPSS 0.35%via NVD
CVE-2026-53756Medium· 4.9PoC
3w ago

Emlog is an open source website building system

Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filt…

▾ Twilightemlog · emlogEPSS 0.43%via NVD
CVE-2026-86097Medium· 6.5PoC
3w ago

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or…

▾ TwilightPX4 · PX4-AutopilotEPSS 0.40%via NVD
CVE-2026-48019High· 8.9PoC
3w ago

Laravel is a web application framework

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may …

▾ Midnightlaravel · frameworkEPSS 0.51%via NVD
CVE-2026-85704Low· 3.7PoC
3w ago

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.41%via NVD
CVE-2026-85703Medium· 6.5PoC
3w ago

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulati…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.55%via NVD
CVE-2026-85702High· 7.3PoC
3w ago

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such…

▾ Midnightramon-victor · freegpt-webuiEPSS 0.66%via NVD
CVE-2026-85701Medium· 5.3PoC
3w ago

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such ma…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.63%via NVD
CVE-2026-85643Medium· 4.7PoC
3w ago

A flaw has been found in code-projects Online Shopping System 1.0

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performe…

▾ Twilightcode-projects · Online Shopping SystemEPSS 0.35%via NVD
CVE-2026-85639Medium· 5.6PoC
3w ago

A security vulnerability has been detected in jofpin trape 2.0

A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The atta…

▾ Twilightjofpin · trapeEPSS 0.35%via NVD
CVE-2026-85638High· 7.3PoC
3w ago

A weakness has been identified in jofpin trape 2.0

A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit h…

▾ Midnightjofpin · trapeEPSS 0.52%via NVD
CVE-2026-79423High· 8.8PoC
3w ago

An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

▾ MidnightEPSS 0.85%via NVD
CVE-2026-75438High· 7.5PoC
3w ago

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

▾ MidnightEPSS 0.82%via NVD
CVE-2026-71626High· 7.5PoC
3w ago

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

▾ MidnightEPSS 0.53%via NVD
CVE-2026-71624Critical· 9.8PoC
3w ago

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

▾ AbyssalEPSS 0.93%via NVD
CVE-2025-67066Critical· 9.8PoC
3w ago

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

▾ AbyssalEPSS 0.50%via NVD
CVE-2026-85636Medium· 5.3PoC
3w ago

A vulnerability was identified in jofpin trape 1.0.0

A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may …

▾ Twilightjofpin · trapeEPSS 0.75%via NVD
CVE-2026-78745Critical· 9.8PoC
3w ago

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-79418High· 8.7PoC
3w ago

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers …

▾ Midnightemxtecnologia · gestao_x_business_suiteEPSS 0.38%via NVD
CVE-2026-85649High· 7.9PoC
3w ago

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate…

▾ MidnightEPSS 0.20%via NVD
CVE-2026-85589Medium· 5.3PoC
3w ago

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks

phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access t…

▾ Twilightthorsten · phpMyFAQEPSS 0.49%via NVD
CVE-2026-85584High· 7.5PoC
3w ago

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policie…

▾ Midnightsiyuan-note · siyuanEPSS 0.59%via NVD
CVE-2026-85579Medium· 4.3PoC
3w ago

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global und…

▾ Twilightsiyuan-note · siyuanEPSS 0.28%via NVD
CVE-2026-77818Medium· 6.1PoC
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Auto…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-85406Low· 3.5PoC
3w ago

A vulnerability has been found in Eleveo Quality Management 9.7.0

A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possibl…

▾ TwilightEleveo · Quality ManagementEPSS 0.33%via NVD
CVE-2026-85399High· 7.3PoC
3w ago

A security flaw has been discovered in code-projects Hospital Information System 1.0

A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument…

▾ Midnightcode-projects · Hospital Information SystemEPSS 0.43%via NVD
CVE-2026-85381Medium· 5.3PoC
3w ago

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.c…

▾ Twilightlight0011 · cmsEPSS 0.57%via NVD
CVE-2026-11613Critical· 9.8PoC
3w ago

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to inclu…

▾ AbyssalEPSS 0.59%via NVD
CVEs tagged “exploit-available” — page 59 · VulnSea